Changelog¶
All notable changes to this project are documented here. The format follows Conventional Commits and this file is generated by git-cliff from the release workflow.
1.7.0 - 2026-10-08¶
Features¶
- examples: Real projects for every non-pixi reader, written by the real tools (#363) (74a5660)
- input: Read pylock.toml (PEP 751) (#364) (aaa8ef0)
- input: Read uv.lock, and find it by the upward search (#366) (bd098da)
- input: Read poetry.lock (lock-version 2.x) (#367) (25abba3)
- input: Read pdm.lock (lock_version 4.x) (#368) (5c65fff)
- input: Read conda-lock.yml (unified, version 1) (#369) (2b82c59)
- input: Read explicit conda spec files (#370) (371cf6d)
- manifest: Declared dependencies beside non-pixi lockfiles (#371) (5978b18)
- pypi: Record Python extras as pixi:python-extras and pixi:via-extra (#372) (5f4599b)
- format: Dependency groups as CycloneDX scope and SPDX dev/optional relationships (#373) (632819a)
- prefix: Describe plain venvs and site-packages, not only conda environments (#374) (acee39e)
- prefix: Mark user-requested packages as direct from REQUESTED (#376) (9e22091)
- prefix: --infer-extras for venvs, labelled as inferred (#377) (7060a59)
- discover: Find every supported lockfile kind in the upward search and --scan (#378) (8e71644)
- diff: --against accepts every supported lockfile, for venv drift checks (#379) (447359b)
- Pre-commit hooks for writing the SBOM and the license gate (#382) (916524b)
- action: Prefix and from-sbom inputs, and a tested example for uv projects (#383) (e85cfc9)
Bug Fixes¶
- format: Lifecycle phase from the input, not always pre-build (#365) (a6a61e6)
- purl: VCS, local and editable installs no longer claim a PyPI purl (#375) (b1053f0)
- test: The never-consulted cache test no longer races the stale test (#387) (a3a7f9d)
- release: Attach the wheels to the release deterministically (#388) (28cfefc)
Documentation¶
- Using pixi-sbom without pixi, and a README that says what it reads (#385) (908f942)
- How to get a lockfile pixi-sbom reads, for every common setup (#390) (ecbc6c2)
- The Pipenv route is for Pipenv-managed projects; a pip venv uses --prefix (#391) (98bb4b8)
Testing¶
- Every report, enrichment and gate on every input kind (#384) (83b4166)
1.6.0 - 2026-10-07¶
Features¶
- vex: Machine-readable justification for not_affected assessments (#338) (e0ab8a9)
- vex: Write analysis.response, and say why the assessment dates are not (#350) (aeb6b0b)
- Default --conda-index-kind to prefix; anaconda stays selectable (#356) (84f9ff6)
Bug Fixes¶
- Let the changelog span prereleases instead of fragmenting on them (#316) (7c9f50e)
- vex: Refuse --vex with --format spdx instead of writing a VEX that links nowhere (#320) (adcf8e9)
- Batched prefix.dev queries never exceed --concurrency (#355) (907d389)
- Show --report outdated progress while prefix.dev batches are in flight (#359) (e02772c)
- Count a batched package as soon as its batch lands (#360) (6a23b9f)
Documentation¶
- Why the two conda index kinds disagree on dates, and on the newest hours (#352) (b62c0ed)
Testing¶
- A local HTTP server, so request behaviour is asserted rather than timed by hand (#351) (86db1a8)
1.5.0 - 2026-10-04¶
Features¶
- Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
- Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
- Say in --doctor how many requests and which conda index (#308) (729812d)
Bug Fixes¶
- Count the network a run used, not the network it could have used (#300) (991b517)
- Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
- Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
- Stop tying requests in flight to the core count (#306) (07eefcc)
- Date a batch's newer releases in parallel, not one after another (#313) (4bdd2f2)
- Count a batched fetch as a fetch, not as a cache hit (#314) (e8e7b75)
- ci: Release the version that was asked for, even with no new commits (#315) (3134602)
Performance¶
- Share one HTTP agent so connections are reused (#301) (c186101)
- Ask prefix.dev about ten packages per request (#309) (d7fd067)
1.4.0 - 2026-10-03¶
Features¶
- Let the configuration file choose the conda index (#286) (d8171ec)
- Read system and user configuration from pixi's directories (#289) (fa3dcd8)
Bug Fixes¶
- Confirm a mirrored package's channel by its hash, not its name (#281) (82df2d1)
- Match the installed build by its build string, not by scanning a page (#283) (e0c1f19)
- Stop blaming credentials for an answer the probe asked for (#290) (f428509)
Performance¶
- Resolve a mirrored channel once, not once per package (#282) (c05ed68)
1.3.0 - 2026-10-02¶
Features¶
- Read the credentials pixi already keeps, for a private channel (#278) (60a93c4)
- Say which credentials a request carried, and fill in the trace level (#279) (c1ccaeb)
1.2.0 - 2026-10-02¶
Features¶
- --conda-index-kind, with prefix.dev as a second conda index (#275) (1a79188)
Bug Fixes¶
- A named conda index is asked about every channel, not only anaconda.org (#274) (2847ee2)
- Prefix.dev dates are the build's own, and selecting an index lifts the filter (#276) (85a1059)
1.1.0 - 2026-10-01¶
Features¶
- --doctor on its own probes every upstream it knows about (#262) (ae13c63)
- PIXI_SBOM_CONDAPKG_URL, with the anaconda spelling kept permanently (#266) (4662b2a)
- Point every upstream at a mirror, archives included (#271) (94dfe38)
- --doctor probes the archive hosts, from the lockfile when there is one (#272) (af67224)
Bug Fixes¶
- --doctor names the conda index by its role, not by a hostname (#264) (115d2b2)
Documentation¶
- The strict attestation check, pinning the release workflow and tag (#246) (3235948)
- A 20-second terminal recording at the top of the README (#249) (ee4b5c8)
- A recording per report in the docs, and make them actually offline (#251) (2b56ded)
- Document the Marketplace listing now that it exists (#253) (62f11db)
- The real numbers in architecture.md, and the modules it left out (#255) (859c95b)
- The site footer says Apache-2.0, which is what the project is (#258) (153947e)
1.0.0 - 2026-09-27¶
Features¶
- --root-name and --outdated-min, with the old spellings kept (#227) (#228) (d45eb61)
- Record vulnerabilities in SPDX 3.0.1 via the security profile (#118) (#229) (7b05001)
- action: A floating v0 tag for Marketplace users, and docs that use it (#231) (238f41f)
Bug Fixes¶
- docs: The config keys on the stability page were in a casing the parser rejects (#242) (62533ab)
- Settle the support policy and harden the tag move before 1.0 (#244) (#245) (a48d23e)
Documentation¶
- Write down what 1.0 freezes, and make the page check itself (#230) (98a068d)
- The 1.0 pass over the docs, and somewhere for release copy to live (#119) (#241) (69db880)
Testing¶
- Check the stability page in both directions, not just one (#232) (18ab185)
0.12.0 - 2026-09-27¶
Bug Fixes¶
- ci: Attest releases from the tag so the provenance names what was built (#218) (#220) (88a368a)
- --no-cache and --refresh now reach the archive caches (#197) (#224) (086cabf)
- ci: Dogfood the action on every platform it claims to support (#225) (#226) (dd6e51c)
Documentation¶
- A verify command that works, and stop shipping a perf dump (#222) (#223) (89d1613)
0.11.0 - 2026-09-27¶
Features¶
- Support every lockfile format pixi has written, and say so (#206) (0ef9dd1)
- Sign build provenance for every release archive (#202) (#213) (ee6cfb9)
Bug Fixes¶
- The MSRV was never 1.85, and nothing was checking (#208) (e13fe1e)
- docs: Move the site toolchain to PyPI to clear PYSEC-2026-2132 (#211) (#216) (68f6747)
- A purl with no version is a name, not an identity (#215) (#217) (05fc3c8)
Documentation¶
- The two presentations, and where their numbers come from (#199) (e545a70)
- The published library is not an API, and now says so everywhere (#210) (e9f90b4)
- A security policy, and a private way to report (#203) (#214) (1fb683e)
0.10.1 - 2026-09-26¶
Performance¶
- Buffer stdout, which a milestone of benchmarks never looked at (#195) (d49c545)
CI and Build¶
- perf: The memory gate goes back to 15% (#196) (2a7779e)
0.10.0 - 2026-09-26¶
Features¶
- A criterion benchmark suite, and a library to point it at (#185) (04aea1a)
- One pool on rayon, sized by PIXI_SBOM_CONCURRENCY (#186) (efc8f77)
- Look every document's packages up once, not once per document (#187) (dcb6cb5)
Bug Fixes¶
- perf: Measure the child, gate on a share and an amount, and record the allocator trade (#192) (0f37f8c)
Performance¶
- Write documents straight out, and bound the license text a document holds (#188) (6f9dc2a)
- A smaller, faster binary — panic=abort and mimalloc (#189) (64fe6ec)
CI and Build¶
- Measure performance on every platform a binary is built for (#191) (c4a0f30)
0.9.5 - 2026-09-26¶
Features¶
- Log every request and the whole error chain behind a failure (#164) (a6c3f31)
- Give every diagnostic a help line naming the next step (#166) (4a3fc07)
- Say which input and which settings a run chose (#167) (9764b1b)
- Say what a run will talk to before it talks to anything (#168) (cd0a6c2)
- Say where every fact about a package came from with --explain (#171) (b587acf)
- --refresh and --no-cache, and say what each cache served (#170) (e25aa50)
- --doctor probes every upstream and says which one is unreachable (#173) (59f15bb)
- Name every gate that fired and the one that chose the exit code (#169) (ced2368)
- --version-details prints what a bug report needs (#176) (e464c30)
- Record in the document when enrichment was incomplete (#160) (#179) (711ed3e)
- An empty vulnerability table says whether anything could be asked (#174) (157c9b5)
- --timings says where the run spent its time (#177) (e0f2175)
- --log-format json, for a collector rather than a person (#181) (5d65d99)
- SOCKS and Windows system proxies, and a private CA bundle (#183) (70ce8f3)
Bug Fixes¶
- Build the Pages artifact from mike's own commit (#165) (6dcaadf)
- Close describe_input, which a rebase resolution dropped (#172) (1466b9f)
- doctor: Count a body past the probe's read cap as an answer (#178) (9fe2c02)
- One stale-cache tally, not two (#180) (5d76c11)
Documentation¶
- List --doctor in the README options and examples (#175) (34c3c36)
- What each log level says, and how to narrow it to one module (#182) (e5b4f38)
0.9.0 - 2026-09-25¶
Features¶
- Render report tables with comfy-table and colour them with --color (753b37d)
- Show progress bars while the enrichment fetches run (e0b4311)
- Flag yanked PyPI releases and gate on them with --fail-on-yanked (cd1f60f)
- Report how far behind its index each package is (3b1890f)
- Report which packages cap the interpreter with --report python (#135) (e46854c)
- Mark the dependencies the workspace declared itself (#136) (a4da5b6)
- Name phantom, undeclared and unused dependencies with --report phantom (#137) (a358b9d)
- Gate a run on what changed with --fail-on-diff (#138) (28a00f9)
- Compare an installed environment with its lockfile (#139) (8492623)
- Describe every workspace in a tree with --scan (#140) (f9cd174)
- Read an existing document with --from-sbom (#141) (2d47b0f)
- Exempt a package from the license policy with --ignore-license (#142) (d98e1b2)
- Write the assessments as a standalone VEX with --vex (#143) (8a019c7)
- Draw the dependency tree and group the licenses view (#144) (6a428f3)
- Read the cargo auditable crate list out of installed binaries (#145) (569c6de)
- Record the OpenSSF Scorecard of each package with --scorecard (#146) (81c7242)
Bug Fixes¶
- Expire the docs repository card cache so it shows the current release (d075ffe)
- Publish the crate from a clean checkout of the release tag (d5de240)
- Keep the batch heading plain in the markdown report (c9e12a5)
Performance¶
- Look PyPI licenses up ten at a time (69735f3)
0.8.0 - 2026-09-21¶
Features¶
- Sign the documents with a GitHub artifact attestation from the action (370adbe)
- Support cargo binstall and publish the crate from the release workflow (900391a)
0.7.0 - 2026-09-21¶
Features¶
- Leave packages out with --exclude, --include and --exclude-kind (9a5cd54)
- Read settings from pixi-sbom.toml or [tool.pixi-sbom] before the command line (381a4ec)
- Report what changed since a previous document with --report diff --against (d81c832)
- Describe an installed environment without a lockfile with --prefix (4336163)
0.6.0 - 2026-09-21¶
Features¶
- Version the docs per release tag with a dev build from main (6f627aa)
- Look up known vulnerabilities on OSV with --vulnerabilities osv (8c08627)
- Add --report vulnerabilities in table, markdown, csv and json (9c2f910)
- Gate on vulnerabilities with --fail-on-severity and accept them with --ignore-vuln (a4c4aab)
- Flag findings in CISA's Known Exploited Vulnerabilities catalog with --kev (175b38d)
- Write vulnerabilities as SARIF and expose the vulnerability flags in the action (0262b24)
Bug Fixes¶
- Keep the pixi-sbom cache inside the pixi cache directory (d4b692e)
Documentation¶
- Note the github-pages environment tag policy releases need (7519e49)
0.5.5 - 2026-09-21¶
Features¶
- Scaffold the MkDocs documentation site (ce1a365)
- Publish the documentation site to GitHub Pages on every release (68142af)
- Link the documentation site and make the action Marketplace-ready (12c0df4)
- Version the documentation site per release with mike (094dbfc)
Documentation¶
- Restructure the site into installation, CLI, action, recipes and formats pages (9d88ab3)
0.5.1 - 2026-09-21¶
Features¶
- Say why a license is not an SPDX expression (0280c50)
- Read small .tar.bz2 archives whole for license details (29a13a7)
Bug Fixes¶
- Capture the pixi-sbom exit status in the action under bash -e (a926a1e)
- Let the action run more than once per job (1a718e5)
- Keep conda-forge's "WITH exceptions" licenses as evaluable expressions (003339a)
0.5.0 - 2026-09-21¶
Features¶
- Add a license policy gate with --allow-license, --deny-license and --require-license (1b0cf29)
- Add a GitHub Action that runs the release binary (012e98c)
- Write SPDX 3.0.1 JSON-LD with --format spdx --spec-version 3.0 (2bcfdf4)
- Attach PEP 770 embedded SBOMs from wheels with --embedded-sboms (9ac664b)
0.4.0 - 2026-09-20¶
Features¶
- Add --fetch-licenses with conda details from the package cache (23a8667)
- Add --report to print package and license tables to the terminal (8d74219)
- Read conda license details from channel archives by HTTP range (77a8597)
- Read PyPI license details from wheels by HTTP range (96099b0)
Bug Fixes¶
- Pin the report table width in snapshot tests (21444c3)
- Make the archive e2e test independent of line endings and drive letters (eaa67ba)
- Render local package paths as file URLs in the document (96ce0ba)
- Emit LicenseRef licenses with texts as named licenses in CycloneDX (1f20b41)
0.3.0 - 2026-09-19¶
Features¶
- Enrich conda packages with PyPI purls so scanners can match them (85ffd58)
- Look up PyPI licenses from the index with --pypi-licenses (2a0f0de)
- Write CycloneDX 1.7 with --spec-version (8b13136)
0.2.0 - 2026-09-19¶
Features¶
- Derive deterministic document ids and honor SOURCE_DATE_EPOCH (cc72a3e)
- Write the SBOM to stdout with --output - (fc1c83f)
- Add --all-platforms, symmetric with --all-environments (9dcd06e)
- Cover CISA 2026 minimum elements (07c8c5a)
- Link PyPI packages to the conda python package (fac06fd)
Bug Fixes¶
- Record the lockfile by name instead of its absolute path (3628bda)
0.1.0 - 2026-09-18¶
Features¶
- Scaffold pixi-sbom Rust extension with CLI and lockfile discovery (eecca4b)
- Build format-agnostic SBOM model from pixi.lock (899cbe9)
- Write CycloneDX 1.6 and SPDX 2.3 JSON documents (b35464d)
- Describe pixi-build source packages from their build source (efabe43)
- Add --all-environments to write one SBOM per environment (9aadfe2)
Bug Fixes¶
- ci: Replace retired macos-13 runner with macos-15-intel (5d80602)
Documentation¶
- Add release workflow, conda-forge recipe, and field mapping docs (f6157b4)
- Add usage, output format, architecture, and development guides (36368d4)